Skip to content

Remove global ATS exception and document Keychain-backed secrets - #1

Open
forbesfields wants to merge 3 commits into
mainfrom
security/keychain-oauth-ats-hardening
Open

forbesfields wants to merge 3 commits into
mainfrom
security/keychain-oauth-ats-hardening

Conversation

@forbesfields

Copy link
Copy Markdown
Owner

UI-side half of the security-hardening pair; core changes are in coderswitch-studio#1.

Changes

  • Remove global ATS exception (audit H-2): drop NSAllowsArbitraryLoads from project.yml and the generated Info.plist. Custom provider endpoints are now validated at save time in the core package (https:// required for non-loopback hosts; loopback http:// allowed; no embedded credentials). Upstream forwarding to non-loopback plain HTTP therefore fails closed, while loopback local-development endpoints keep working (ATS exempts loopback by default).
  • SECURITY.md: Secret Handling and Known Hardening Items updated to reflect what now exists — Keychain-backed SecretBox root key with automatic .master.key migration, Keychain proxy admin key, OAuth state validation, loopback-only callback listener — and what remains (Google client secret rotation, sandbox decision, post-migration key rotation).
  • Ran xcodegen generate; verified with plutil -lint and confirmed the built app bundle contains no NSAppTransportSecurity key.

Verification

  • xcodebuild -scheme CoderSwitch -configuration Debug build: BUILD SUCCEEDED
  • Built app Info.plist: no NSAppTransportSecurity entry
  • Core test suite (swift test in coderswitch-studio/Packages/CoderSwitchCore): 81 passed, 0 failures
  • Live runtime check against real data: proxy /healthz → {"ok":true}, unauthorized /v1/models → 401

Notes

  • README.md has unrelated uncommitted edits (not part of this PR, left in the working tree).
  • PROGRESS.md is gitignored; the changelog entry for this hardening work was updated locally.

- Drop NSAllowsArbitraryLoads from project.yml and Info.plist; custom
  provider endpoints are validated at save time in CoderSwitchCore
  (https required off-loopback).
- SECURITY.md: Secret Handling and Known Hardening Items now reflect
  the Keychain-backed SecretBox root key, Keychain proxy admin key,
  OAuth state validation, and loopback-only callback listener.

Pairs with the coderswitch-studio core PR (secret migration, OAuth
state/callback hardening, endpoint validation, migration tests).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant